Security & Trust
Bank-hosted by design.
Current posture as of September 18, 2026
KeptCap's target architecture keeps the customer-data processing plane inside the bank-controlled environment. The public Vercel demo contains synthetic data only.
Architecture principles
Bank-local data plane
Customer IDs, balances, rates, transactions, counterparties, decisions, and outcomes are designed to remain inside the institution-controlled environment.
Read-only pilot posture
The pilot does not require core write-back, autonomous pricing, money movement, or autonomous customer communication.
Deterministic decisions
Material risk and economic calculations are rule-based, versioned, and designed to be reproducible from bank-approved facts and configuration.
Hard-data standard
Runoff decisions use auditable inputs such as balances, transaction movement, rates, CD maturity, uninsured exposure, loans, treasury activity, and funding assumptions.
Data minimization
KeptCap does not require card PAN, CVV, online-banking passwords, customer passwords, or Social Security numbers for the commercial-deposit decision workflow. Early pilots can use masked or pseudonymous identifiers where appropriate.
Current pilot controls
| Control | Status | Current approach |
|---|---|---|
| Bank-hosted application and database | Implemented | Containerized application with bank-local PostgreSQL reference runtime. |
| Outbound mode disabled by default | Implemented | The reference pilot does not require customer-data egress. |
| Validated data ingestion | Implemented | Required-field, type, institution, checksum, and duplicate-import controls. |
| Audit history | Implemented | Imports, decisions, configuration changes, actions, and outcomes are recorded locally. |
| Configuration versioning | Implemented | Bank policy inputs are validated, versioned, and tied to decision evidence. |
| SSO / bank identity | Institution-specific | Production direction is SAML or OIDC with bank-managed identity and MFA. |
| KMS, SIEM, backups, image scanning | Institution-specific | Mapped to the bank's approved cloud and security standards during deployment. |
AI boundary
AI is not required for the pilot decision engine. If a narrative layer is added later, it should remain evidence-bound and should not perform the financial math or alter the underlying deterministic recommendation.
Assurance posture
KeptCap does not currently represent that it has completed SOC 2 or ISO 27001 certification. Those programs, penetration testing, formal vulnerability management, incident response, business continuity, and related production controls are part of the production-readiness roadmap and buyer requirements.
Public demo boundary
app.keptcap.com is a synthetic product demonstration. No real bank customer data should be submitted there. Institution pilots use the separate bank-hosted runtime and institution-specific security controls.
Security and vendor-risk inquiries
For architecture, vendor-risk, security questionnaire, or pilot-security discussions, contact hello@keptcap.com.